Skip to content
Back to skills

Cmd Brain

ASecurity

Manage the engagement brain. Subcommands: 'init' to set up, 'brief <target>' for pre-flight, 'status' for overview, 'exhausted [target]' to see dead ends.

  • 815 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added May 29, 2026
ai-agentspython

Security analysis

A100/100

Scanned May 29, 2026

npx -y skills add H-mmer/pentest-agents --skill brain --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Cmd Brain?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Cmd Brain
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/h-mmer-cmd-brain/badge)](https://www.skillsdirectory.com/skills/h-mmer-cmd-brain)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: brain
description: "Manage the engagement brain. Subcommands: 'init' to set up, 'brief <target>' for pre-flight, 'status' for overview, 'exhausted [target]' to see dead ends."
---

Brain management: $ARGUMENTS

Route to the brain tool:
- If "$ARGUMENTS" is "init": run `uv run python3 ../../tools/brain.py init`
- If "$ARGUMENTS" starts with "brief": run `uv run python3 ../../tools/brain.py brief <target>`
- If "$ARGUMENTS" is "status": run `uv run python3 ../../tools/brain.py status`
- If "$ARGUMENTS" starts with "exhausted": run `uv run python3 ../../tools/brain.py exhausted <target>`
- If "$ARGUMENTS" starts with "record": run `uv run python3 ../../tools/brain.py record <target> <status> <technique> "<details>"`

After running, also launch the `brain` agent to update the MEMORY.md index if any state changed.

## Top-Tier Memory Bar

Bad memory makes the whole suite worse. Record facts as reusable evidence, not diary entries.

For every record, include:
- `target`: canonical host or repo name
- `surface`: endpoint, file, workflow, account role, or component
- `technique`: vuln class plus variant, not just "tested auth"
- `status`: confirmed, partial, exhausted, blocked, duplicate-risk, chain-pending
- `evidence`: request id, file path, response marker, screenshot path, command output, or blocker
- `next_action`: the exact command or test a future session should run

Never store "no bug" without the tested matrix. An exhausted entry must say what was tried and why that evidence is strong enough to skip it later.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…